CEH Practical Syllabus Changed | Updated

Поделиться
HTML-код
  • Опубликовано: 18 ноя 2024

Комментарии • 85

  • @thepentesterguyofficial
    @thepentesterguyofficial  Год назад

    Kindly go through each comment, every one has shared their new exam experience it will help you all.

  • @AislinnT
    @AislinnT 6 месяцев назад +3

    A warning to everyone about the servers --- I took my exam this week and the servers where the servers are super slow each click took at least 1 second. For the questions that required multiple steps like scanning for the ports and then enumerating over them, and then gaining access, it took a really long time especially when you have refer back to another terminal for the IP addresses. With 3 subnets, you can imagine that the list of machines is pretty long so imagine the scrolling you have to do and the slow speed of scrolling!
    I had copied them into a .txt file on the VM desktop (you cannot copy them to your own desktop) but the speed to open the txt file each time was still super slow! You are not allowed any pen and paper so you cannot write them down - which in a real life scenario is possible!
    Most of the time is actually spent on this and I did not have enough time to complete it. EC-Council refuses to admit that and said that "you are supposed to scan the target subnets first completely". That was what I did but it does go beyond scanning the subnets isn't it ???
    It is really a SHAM from EC-Council considering that people paid some significant amount of money for this.

  • @nafizurrahman2569
    @nafizurrahman2569 Год назад +14

    So its not just me. I was preparing keeping in my mind the old syllabus and trust me immediately after reviewing the questions in the exam which i appeared 1 week back i knew i am not gonna pass this . . So just tried my best to stay calm and solve the questions.
    Question pattern-
    1. There is now 3 /24 subnets to scan with many machines hosted with variety of services including Active Directory! Though no questions was related deeply with Active Directory.
    2. Faced questions related to new topics mentioned in this video like vuln scan, malware analysis, privilege escalation, RAT etc
    3. Questions from wireshark is changed, included IoT protocols and cracking wireless encryption using pcap traces.
    4. Web exploitation questions are not so simple like previous. Faced almost 4-5 questions alone in this domain.
    5. All questions are made complex. Even easy questions are convoluted to just kill your time :) . . Like the question relating to openstego, i was asked to decode the secret message in image file. The password was in a text file. So I checked the text file i found a hash there ! So have to decrypt the hash first. Hash type is not mentioned so you have to identify the hash type ! VM has no internet and the copy/pasting from VM to my browser was NOT allowed! Then i used another tool named hash identifier to identify the hash. Then used john the ripper to crack it . . Then was able to use the cracked password for openstego question! Similarly had to crack hash in veracrypt question but this time hash type was mentioned i think. Just imagine encountering this during exam !
    Exam Experience:
    - exam VM was slower as it loaded in browser.
    - since i have given exam in laptop it become so hot after using the exam environment for 6 hour.
    - the writings on the VM is so slow that most of the time had to get very close to see the output.
    - i think in one question there was bug. Like i was told to crack SMB credentials and get a file from share. Cracked the credentials but was unable to mount to SMB share using different tools!
    - my personal opinion is 6 hour is not enough to solve all the 20 questions! U may pass but achieving 20/20 in 6 hour u have to be a PRO i think!

    • @heinenk
      @heinenk Год назад +3

      Had a question about FQDN of the domain controller, and it would just not accept my reply, another one was decrypt a 384 hash, and enter last 4 digits. It refused to accept that. Ohh and ofc, "sticky" keys like crazy, when trying to type a command or password, it would keep writing letters. Another challenge was since I am not a US keyboard user, I could not change keyboard layout. So typing in chars when not used to US keyboard was a pain in the a... :)

    • @nafizurrahman2569
      @nafizurrahman2569 Год назад +2

      ⁠@@heinenk yes, got this issue of writing multiple letters at a row several times and had to correct it too ! I am done with EC council. . Not again. . PJPT dropped today and i think i will go for it next . .

    • @harshbanshpal
      @harshbanshpal Год назад

      @@nafizurrahman2569 I faced this too.

    • @RomanLokesh-g2r
      @RomanLokesh-g2r Год назад

      I'm going to. write an exam can anyone give some questions like

    • @destinadams8713
      @destinadams8713 Год назад

      I took it on Friday and experienced the same thing.

  • @MDroid-bn6eb
    @MDroid-bn6eb Год назад +3

    the new exam are indeed way harder, but not impossible. flags are no longer in plain sight, and you are deliberately made to work for them by going an extra step or two. for example, flags are stored in hidden directories, flag values with hash that you have to calculate separately, etc. so get good with your shell commands, linux, nmap and all the common tools. all the best!

  • @augustinenzewi5227
    @augustinenzewi5227 Год назад +2

    Passed My CEH Practical Exam today June 14, 2023. Thanks for this update. I saw this video few minutes to my exam.

    • @thepentesterguyofficial
      @thepentesterguyofficial  Год назад

      Congratulations 🎉

    • @augustinenzewi5227
      @augustinenzewi5227 Год назад

      @@thepentesterguyofficial Thank You.

    • @PedroSouza-lc5qz
      @PedroSouza-lc5qz Год назад

      you had priv escalation? wifi and iot? easy or not? thanks!

    • @augustinenzewi5227
      @augustinenzewi5227 Год назад

      @@PedroSouza-lc5qz there is WiFi, and IoT. Learn how to analyse pcap using wireshark. Also how to crack wireless pcap captures. U need to understand privilege escalation to enable capture the flags. Some flags are encrypted within a file or folder which u need to decrypt.

    • @PedroSouza-lc5qz
      @PedroSouza-lc5qz Год назад

      @@augustinenzewi5227 Thanks!! And the softwares to decrypt files or folders within the Parrots OS or i need to download them? One question if nobody said to me, can i use chatgpt? :)

  • @gco8903
    @gco8903 Год назад

    This video is accurately correct
    Exam has been exam very much
    We have 3 subnets with 4-5 machines in each
    Question have been merged into once questions like after solve you will get hash to becode after enumerations
    LAB is very slow for these merged questions
    I brealy Cleared 18 questions in complete 6 hours
    Initially i had believed i can clear 20 questions in just 2 hours but questions are really changed now
    We have to do enumeration for each question
    By the way IoT, Vulnerabilities Analysis, wi-fi and Priv Esc part are added but they are very easy
    But be prepare to enumerate 3 subnet in small and laggy screen/machines for each question and you have to use answer to exploit again or crack (no 1 step answers)
    And LAB in buggy as after exploiting web vulnerability you can't get shell even on p80 443
    In Malware analysis, given file was not opened with any of tool given in lab and displayed currupt file error

    • @topwarivergamevip03785
      @topwarivergamevip03785 Год назад

      is shasum -a 384 file.elf right?

    • @AdekunleToluwalase-n6y
      @AdekunleToluwalase-n6y Год назад

      Hello if you don't mind can you explain the priv esc part. or if there's a way i can contact you, maybe you can drop your telegram username. if you don't mind. Thanks

    • @PedroSouza-lc5qz
      @PedroSouza-lc5qz Год назад

      can i use chatgpt? kkkk for malware analysis is good:) did you do the exam in this days?

    • @Halalela25
      @Halalela25 Год назад

      did you use ssh and polkit vulnerability for the priv esc question and what did you have to do for the iot question

  • @MultiSammy1010
    @MultiSammy1010 Год назад +2

    Thanks for the update @thepenterguy. 😊😊 Heard you loud and clear.

  • @leandrourena215
    @leandrourena215 2 месяца назад

    I had a question where they asked me for the value of page_ID=95, I looked at the source code of the given domain and there was a value in page_Id=95 but it gave me an error, I couldn't solve it. Any suggestions?

  • @BalramPutin
    @BalramPutin Год назад +1

    Could you make a video on how to become an appsec engineer or analyst? From beginner. Please, Thank you.

  • @SkyEagle-v1k
    @SkyEagle-v1k Год назад +1

    Can you please make and share small videos on new topics

  • @kumarvarma790
    @kumarvarma790 Год назад

    How covert tcp question is asked and how can we identify and solve it

  • @rpuri84
    @rpuri84 8 месяцев назад

    Since CEH practical is an open book exam, can CEH official Lab guide be printed in the PDF format and referred during the exam?

  • @kroens2305
    @kroens2305 Год назад +1

    Any update on the new questions?

  • @chilltooki
    @chilltooki Год назад +1

    Do we have any new updates/tips on the latest qs?

  • @kumarvarma790
    @kumarvarma790 Год назад

    true bro, the cloud machines are really very slow

    • @usamaabid7313
      @usamaabid7313 Год назад

      Sir, Cloud kay baray mai kia question aya tha?

  • @plussecurity
    @plussecurity Год назад +1

    exam ma bhaiya joo v topic change wo aa haa us per video panaye

  • @Ashish-ml7wy
    @Ashish-ml7wy Год назад

    malware analysis main agr virus total kah use kre toh answer hojayega kya

  • @ByD27CoD
    @ByD27CoD Год назад

    Some one knows how priv esc question? And how to tranfers files between attacker machines?

  • @lekebello2422
    @lekebello2422 Год назад

    Where can I get the old questions from (the questions that remains unchanged)

  • @davidp2652
    @davidp2652 Год назад

    Hi, somebody know how we get the FQDN?

  • @heinenk
    @heinenk Год назад

    Learned this the hard way yesterday 😊

  • @lekebello2422
    @lekebello2422 Год назад

    Hello how can I reach out to you personally and ask questions

  • @PedroSouza-lc5qz
    @PedroSouza-lc5qz Год назад

    Hi my friend ! Are you sure you fall on exam the malware analysis and privilege escalation? on the practice exam an d not just in theoretical? I bought the exam and took the content within the exam proposal and didn't have it, I did it yesterday, aren't those presented only for the theoretical test?

  • @maddhukamabampati496
    @maddhukamabampati496 Год назад

    Hey, Can you make Vedios on new topics

  • @plussecurity
    @plussecurity Год назад

    Mara exam voucher ka validation sarf 1.5month baki haa too kya kera

    • @thepentesterguyofficial
      @thepentesterguyofficial  Год назад

      Fir to attempt krna padega 10 to ho jaenge baki 5-6 k lia aur b padhna padega

    • @usamaabid7313
      @usamaabid7313 Год назад

      Sir, baki topics sai related kuch resources share kardain.

    • @plussecurity
      @plussecurity Год назад

      @@thepentesterguyofficial kya kya padhna padaga and ceh v12 ka lab manaual sa complete hop jayaha kya

    • @thepentesterguyofficial
      @thepentesterguyofficial  Год назад

      @@plussecurity I guess atleast paas to ho jaenge, manual se

    • @plussecurity
      @plussecurity Год назад

      @@thepentesterguyofficial ek video banaye ceh practical ke related aap bola tak 3 month baad exam danaa abhi three months ho chuka haa ab kya kera

  • @AkashSharma-ml2lz
    @AkashSharma-ml2lz Год назад

    Bro what kind of things can we do during exam? I mean can we watch tutorials of the tools on youtube if we don't know the answer? Or can we use chatgpt, or any other google sites if we dont know something?

    • @thepentesterguyofficial
      @thepentesterguyofficial  Год назад

      As far as know we can Google but I am not sure about RUclips you can keep it as option and ask the invigilator before exam if he allows then it's well and good

  • @abuzarkhan1841
    @abuzarkhan1841 Год назад

    Hii i have ceh v11 practice, so the question would be old for it or for v11 also got updated?

    • @thepentesterguyofficial
      @thepentesterguyofficial  Год назад

      Old

    • @abuzarkhan1841
      @abuzarkhan1841 Год назад

      Are sure? Because i am totally rely on this video

    • @abuzarkhan1841
      @abuzarkhan1841 Год назад +1

      Old content, i hope to find old content

    • @thepentesterguyofficial
      @thepentesterguyofficial  Год назад

      @@abuzarkhan1841 bro, I am not the member of Ec Council, I can't take guarantee, but I believe if it's old then there are more chances, you must cover other topics as well

  • @betsythomas5971
    @betsythomas5971 Год назад

    Can we use youtube during the exam?

  • @pranavk95
    @pranavk95 Год назад

    I paid for CEHv11 Practial, will my exam be for cehv12 or 11.
    Also is this playlist of yours sufficient as the only resource to pass the exam? Please upload videos on all the topics. I’m very nervous and have less time left

    • @ManjeetSingh-rc8du
      @ManjeetSingh-rc8du Год назад

      it will be v12

    • @pranavk95
      @pranavk95 Год назад

      @@ManjeetSingh-rc8du so the certificate will also be v12. Damn am worried since v12 is tough